[Back to the takedown index](https://takedownindex.org/takedowns)

# Dridex/Bugat/Cridex disruption

October 2015, Malware and botnets
Led by [Federal Bureau of Investigation](https://takedownindex.org/organizations/federal-bureau-of-investigation), [National Crime Agency](https://takedownindex.org/organizations/national-crime-agency)

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Botnet infrastructure sinkholed/disrupted; UK technical action plus a US civil restraining order/injunction redirected portions of the infrastructure.

[See what happened](#what-happened)

What happened to the people?

Officials reported 1 charged and 1 apprehended.
1 charged and 1 apprehended named in the public record.
Group accounted for: Partial

[See people and accountability](#people)

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

[See what happened afterward](#afterward)

## What happened

FBI/DOJ and UK NCA, with international partners, sinkholed and disrupted infrastructure for the Dridex banking-malware botnet; alleged administrator Andrey Ghinkul was federally charged and arrested in Cyprus at US request.

**Date:** October 2015

**Target:** Dridex (also known as Bugat/Cridex), banking trojan botnet

**Activity:** Malware and botnets

**Operational lead:** FBI and NCA

**Jurisdiction:** Not established

**Outcome:** Botnet infrastructure sinkholed/disrupted; UK technical action plus a US civil restraining order/injunction redirected portions of the infrastructure.

**Status:** Completed

**Legal mechanism:** Federal criminal charges; civil restraining order/injunction; UK technical action.

**Group accounted for:** Partial

## People and accountability

Named in the public record: 1 charged and 1 apprehended.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

Reported and named. Officials reported 1 charged and 1 apprehended. 1 charged and 1 apprehended named in the public record. The two figures come from different places and are never added together. Officials publish a headline total, and this index counts only the individuals it can name from the cited record.

#### Andrey Ghinkul

Alleged administrator of Dridex. Current public status: Arrested and Charged.

**Charging authority:** Federal Bureau of Investigation

**Main charges:** Conspiracy; Computer fraud; Bank fraud

**Case number:** Not established in the public record

**Arresting authority:** Not established in the public record

**Arrest location:** Cyprus

**Extradition status:** Not established in the public record

**Conviction or plea:** Not established in the public record

**Sentence:** Not established in the public record

**Segment:** Core operator

**Sources:** [[1]](#source-1)

**Full record:** [Everything indexed for Andrey Ghinkul](https://takedownindex.org/people/andrey-ghinkul)

Group accounted for: Partial

Sole named alleged administrator charged and arrested; the Dridex family and related operators persisted in later forms.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/dridex-bugat-cridex-disruption/organizations)

## What happened afterward

Not established in the public record. No later activity is recorded against this entry.

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### Official sources

1.
[Dridex botnet disrupted; administrator Andrey Ghinkul charged](https://takedownindex.org/sources/us-doj-fbi-uk-nca-dridex-botnet-disrupted-administrator-andrey-ghinkul-charged)

US DOJ / FBI / UK NCA, October 13, 2015, Source grade S2

Establishes the Dridex disruption and the charge/arrest of Andrey Ghinkul in Cyprus.

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source\_quality capped at S2/P2 pending a dedicated verification pass.

Research context

## How this entry was checked

This entry came from a broader aggregation pass and has not been independently verified source by source. Its sources are graded no higher than P2 or S2, and most carry no address yet. Treat the figures as a research lead rather than a settled record.

Source review: Extended pass, not yet verified

Sources cited: 1

Research cutoff: August 20, 2026

Last reviewed August 21, 2026

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Darkode forum takedown](https://takedownindex.org/takedowns/darkode-forum-takedown)
- [Operation Source / Beebone botnet disruption](https://takedownindex.org/takedowns/operation-source-beebone-botnet-disruption)
- [Operation Pacifier / Playpen](https://takedownindex.org/takedowns/operation-pacifier-playpen)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about#corrections-and-updates)
